...
首页> 外文期刊>International Journal of Applied Engineering Research >Risk Centric Threat Modeling - A Misuse Case based approach
【24h】

Risk Centric Threat Modeling - A Misuse Case based approach

机译:风险中心威胁建模 - 一种误用的基于案例的方法

获取原文
获取原文并翻译 | 示例
           

摘要

In fact, security is an inevitable and common concern nowadays, ensuring it early in SDLC may significantly reduce risk, time and effort. Moreover, it enhances reliability and quality of the applications. Consequently, it establishes the confidence of user with the product. Misuse Case, a classical and effective modeling technique, which has been widely used for eliciting and modeling security threats at the requirements stage. However, this technique lacks the ability to model 'assets, vulnerabilities and risk', which are important risk-related concepts. In order to incorporate such risk related concepts, we propose an idea of extending misuse case model in line with the ISSSRM model. Thereby, we propose an extended version of misuse case model, which incorporates 'assets, vulnerabilities and risk-spots'. Further, a modeling process has also been suggested for helping the designers to model security related risks in an effective manner during the requirements phase, itself. Furthermore, the model is validated using a case study on an e-voting system.
机译:事实上,安全是一种不可避免的和共同的关注,在SDLC早期确保它可能会显着降低风险,时间和努力。此外,它提高了应用的可靠性和质量。因此,它建立了用户对产品的置信度。滥用案例,一种经典和有效的建模技术,已广泛用于诱因和建模要求阶段的安全威胁。但是,这种技术缺乏模拟“资产,漏洞和风险”的能力,这是重要的风险相关的概念。为了纳入这样的风险相关的概念,我们建议符合ISSSRM模型的滥用案例模型。因此,我们提出了一个扩展版本的滥用案例模型,它包含“资产,漏洞和风险点”。此外,还提出了一种建模过程,以帮助设计人员在需求阶段本身以有效的方式模拟安全相关风险。此外,使用对电子投票系统的案例研究验证该模型。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号